Friday, September 18, 2026

How wallet clustering de-anonymizes criminal wallets

Investigation
By Scorechain Team

Quick overview

Produced in association with SafeHorizon, the Horizon Europe project on detecting and disrupting crime-as-a-service, in which Scorechain is the blockchain-analytics partner.

A criminal can hold thousands of wallet addresses, and a fresh one costs nothing to generate. That is why chasing individual addresses rarely resolves a case. What resolves it is joining those addresses back together and attaching them to the entity that controls them. Wallet clustering and entity attribution are the two techniques that make that possible, and together they are how investigators turn a scatter of pseudonymous addresses into a named operation.

What is wallet clustering?

Wallet clustering is the process of grouping multiple blockchain addresses into a single unit based on evidence that one actor controls them all. It relies on behavioural and structural patterns in on-chain data, such as addresses spent together in one transaction, rather than any personal information. The result is a cluster: a set of addresses that behave as one wallet, which investigators can then trace and attribute as a unit.

Clustering is the first half of de-anonymization. On its own it does not name anyone; it establishes that a group of addresses share an owner. Entity attribution, covered further down, is the second half that connects that owner to a real-world identity.

From pseudonymous addresses to a named entity Pseudonymous addresses many addresses, one actor Wallet clustering One cluster grouped by shared control Entity attribution Named entity Exchange / mixer Suspect / service off-chain evidence added

From pseudonymous addresses to a named entity

Pseudonymous addresses
many addresses, one actor
Wallet
clustering
One cluster
grouped by shared control
Entity
attribution
Named entity
Exchange / mixer
Suspect / service
off-chain evidence added
From pseudonymous addresses to a named entity: wallet clustering groups the addresses one actor controls, then entity attribution assigns the identity.

Why a wallet is not an identity

A blockchain address is a pseudonym, not a name. It records that value moved, not who moved it, and one person or service can sit behind millions of addresses. That gap is what criminals exploit when they split funds across new addresses to look like unconnected parties.

Clustering closes the gap by treating control, not the address, as the unit of analysis. Once addresses are grouped by shared control, the number of addresses an actor uses stops being a defence, because the behaviour that links them survives every new address they generate.

The clustering heuristics investigators use

Clustering is driven by heuristics, repeatable patterns that indicate shared control. Investigators rarely rely on one in isolation; the confidence comes from several pointing the same way. The main heuristics are:

  • Common input ownership (co-spend). When several addresses are used together as inputs to one transaction, they are almost always controlled by the same actor. This co-spend heuristic is the foundation of clustering on Bitcoin and other UTXO chains.
  • Change address detection. Spotting the address that receives the change from a transaction links it back to the sender's cluster.
  • Deposit address reuse. Reused deposit addresses and predictable funding patterns group addresses on account-based chains.
  • Wallet software fingerprinting. The way a particular wallet builds transactions, its fee logic, input ordering, and structure, leaves a signature that ties addresses to the same software and often the same operator.
  • Temporal behaviour. Consistent timing patterns across addresses add supporting evidence when the structural heuristics are ambiguous.

No heuristic is infallible, which is why serious clustering combines them and records a confidence level rather than a binary claim.

Common input ownership (co-spend) heuristic Inputs Outputs Address A Address B Address C Same controller One transaction Payment Change address Addresses A, B, and C were spent together, so one actor almost certainly controls all three.

Common input ownership (co-spend) heuristic

Inputs
Address A
Address B
Address C
Same controller
One transaction
Outputs
Payment
Change address
Addresses A, B, and C were spent together, so one actor almost certainly controls all three.

The common input ownership (co-spend) heuristic: addresses spent together as inputs to one transaction are almost certainly controlled by the same actor.

How clustering differs on Bitcoin and Ethereum

Clustering method depends on the ledger model. Bitcoin and other UTXO chains lend themselves to co-spend analysis, because a single transaction can draw on many inputs and expose shared control directly. Account-based chains such as Ethereum work differently: value moves between persistent accounts rather than unspent outputs, so co-spend rarely applies. There, clustering leans on contract and administrative-key relationships, deposit-address reuse, and interaction patterns. The distinction matters because a criminal moving value across both models forces investigators to switch techniques mid-trace, which is where breadth of chain coverage becomes decisive.

Clustering depends on the ledger model Bitcoin and UTXO chains Cluster by co-spend of shared inputs Input A Input B Input C Transaction shared inputs Many inputs in one transaction reveal shared control. Ethereum and account-based chains Cluster by reuse and key relationships Deposit-address reuse Admin-key relationship Co-spend rarely applies, so clustering leans on reuse and control links.

Clustering depends on the ledger model

Bitcoin and UTXO chains

Cluster by co-spend of shared inputs

Input A
Input B
Input C
Transaction shared inputs

Many inputs in one transaction reveal shared control.

Ethereum and account-based chains

Cluster by reuse and key relationships

Deposit-address reuse
Admin-key relationship

Co-spend rarely applies, so clustering leans on reuse and control links.

Clustering depends on the ledger model: UTXO chains cluster by co-spend of shared inputs, while account-based chains cluster by deposit-address reuse and administrative-key relationships.

From clusters to entities, how attribution works

Entity attribution is the step that assigns a real-world identity to a cluster. Clustering says a group of addresses share an owner; attribution says who that owner is, whether an exchange, a mixer, a sanctioned entity, or a named suspect. It combines the on-chain cluster with off-chain evidence: know-your-customer records, seizure data, court filings, and open-source intelligence.

Good attribution is disciplined about certainty. Analysts distinguish the operator who controls the keys from the beneficiary who holds funds through someone else's infrastructure, and they record a confidence level, high, moderate, or low, for every claim. The output lives in an attribution database with documented evidence and an audit trail, so a label can be defended later rather than merely asserted. That documentation is what separates an investigative lead from evidence that holds up under scrutiny.

De-anonymizing criminal wallets in practice

Put together, clustering and attribution let an investigator start from one address, expand it into the full cluster the actor controls, and attach that cluster to an identity or a known service. A ransomware payment address becomes a window onto the operator's entire wallet, and the off-ramp where funds reach a regulated exchange becomes the point at which identity can be compelled.

Criminals push back with mixers, tumblers, and cross-chain bridges designed to break the links clustering depends on. These techniques raise the cost of attribution, but they leave their own patterns, and combining heuristics across chains often re-establishes the trail where a single heuristic fails. The practical goal is not certainty on every hop; it is a defensible chain of reasoning from the criminal wallet to a point of identification.

Limitations and evidential standards

Clustering is probabilistic, and treating it as fact is a mistake. Heuristics can over-cluster, pulling unrelated addresses into one group, or under-cluster when an actor deliberately avoids co-spending. False positives carry real consequences when a label drives a compliance decision or an investigation, so confidence levels and documented evidence are not optional niceties. In court, attribution evidence is tested against admissibility standards, and an unexplained or black-box cluster is a weak foundation. Transparent, auditable methodology is what makes clustering usable as evidence rather than just intelligence.

How Scorechain de-anonymizes criminal wallets

Scorechain builds clustering and entity attribution into investigation tooling designed for institutional and law-enforcement environments. Scorechain Investigator groups addresses under a single controller through entity clustering and attribution, then matches those clusters against a database of more than 939,000 labelled on-chain entities, all on Scorechain's Digital Asset Intelligence graph. It takes an analyst from a single address to a complete, documented case.

The methodology is transparent by design. Investigator's risk score runs on a scale of 0 to 100 where a lower score signals higher risk, and it is auditable, so an analyst can see the reasoning behind a rating rather than trusting a black box, which matters directly for evidential weight. Flux Analysis visualises the fund flows and indirect exposure across protocols and chains that clustering surfaces, Wallet Screening checks an address and its cluster against the same labelled-entity database, and coverage across 25+ blockchains with 2,800+ VASP entries gives investigators the cross-chain reach that de-anonymization increasingly demands. Scorechain works alongside the wider blockchain-analytics field, including providers such as Chainalysis, Elliptic, and TRM Labs, as European-native infrastructure aligned with MiCA and AMLD6 and trusted by 350+ compliance and digital-asset teams.

This is also the on-chain layer Scorechain contributes to SafeHorizon, the Horizon Europe project working to detect and disrupt crime-as-a-service across the web, deep web, and darknet. As its blockchain-analytics partner, Scorechain provides the blockchain intelligence, transaction analysis, and investigation tools to trace cryptocurrency flows linked to cybercriminal activity, and clustering with entity attribution is where that work begins.

Pseudonymity was never anonymity. With disciplined clustering and well-documented attribution, a criminal's growing pile of addresses becomes the very thing that gives them away.

If your team is building crypto investigation or AML capability, book a Scorechain demo to see wallet clustering, entity attribution, and cross-chain tracing applied to your own cases.

Frequently asked questions

What is wallet clustering?

Wallet clustering is the process of grouping multiple blockchain addresses into a single unit based on evidence that one actor controls them all, using behavioural and structural patterns in on-chain data rather than personal information. The result, a cluster, lets investigators trace and attribute many addresses as one wallet instead of chasing each address separately.

What is the common input ownership heuristic?

The common input ownership heuristic, also called co-spend, is the principle that when several addresses are used together as inputs to a single transaction, they are almost always controlled by the same actor. It is the foundation of clustering on Bitcoin and other UTXO-based blockchains, though it is combined with other heuristics to raise confidence.

Can you identify who owns a crypto wallet?

Often, yes, though not from the blockchain alone. Clustering groups the addresses an actor controls, and entity attribution connects that cluster to a real-world identity using off-chain evidence such as KYC records, seizure data, and open-source intelligence. Identification is strongest at regulated off-ramps, where an exchange can compel identity.

Are crypto wallets anonymous, and can crypto be traced?

Crypto wallets are pseudonymous, not anonymous. Addresses do not carry names, but every transaction is permanently recorded and openly queryable, so clustering and attribution can often trace funds and link addresses to an entity. Mixers and bridges raise the difficulty, but they leave patterns of their own.

What is the difference between wallet clustering and entity attribution?

Wallet clustering groups addresses that share a single controller; entity attribution names that controller. Clustering is a structural, on-chain step that says a set of addresses behave as one wallet. Attribution adds off-chain evidence to say who the wallet belongs to, with a documented confidence level. De-anonymization needs both.

How does clustering differ on Bitcoin and Ethereum?

On Bitcoin and other UTXO chains, clustering relies mainly on co-spend analysis, because one transaction can combine many inputs and expose shared control. Ethereum and other account-based chains move value between persistent accounts, so clustering leans instead on contract and administrative-key relationships, deposit-address reuse, and interaction patterns.

Share

Summarize with AI

Want to see how Scorechain can help you trace illicit crypto flows and strengthen compliance?

Be the first to get news from Scorechain

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

350+ COMPLIANCE &  DIGITAL ASSET TEAMS TRUST US